CVE-2022-0563: Medium severity util-linux vulnerability
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2022-0563.
What software is affected by this vulnerability?
The util-linux chfn and chsh utilities when compiled with Readline support, as well as the NetApp ONTAP Select Deploy administration utility.
What is the severity level of CVE-2022-0563?
The severity level of CVE-2022-0563 is medium, with a severity value of 5.5.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-209.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [Link 1](https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w@ws.net.home/T/#u) and [Link 2](https://security.netapp.com/advisory/ntap-20220331-0002/).